
A threat actor has compromised the upstream infrastructure of BdThemes, a developer of popular premium WordPress design plugins, and weaponized it against the company’s own customers. The attackers modified a remote JSON feed that BdThemes plugins fetch and process in site administrators’ browsers — turning that routine update mechanism into a vehicle for creating unauthorized admin-level accounts on affected WordPress installations.
BdThemes produces a suite of widely-used plugins: Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit. All of them were pulled from the WordPress Plugin Directory following the discovery, with the WordPress Plugins team closing them pending a full security review. The attack falls under the classic supply-chain pattern — rather than targeting individual sites directly, the attacker hit the developer’s own infrastructure and used it to reach all sites that run the compromised software.
How to check if you’re affected
Affected products include any WordPress site running Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, or Ultimate Store Kit. If you have any of these plugins installed, go to Users → All Users in your WordPress admin panel and look for unfamiliar admin accounts that you did not create. Any account you do not recognize should be treated as hostile and removed immediately. Also disable or uninstall the affected BdThemes plugins until the WordPress.org review is complete and patched versions are available.
